CWE-400
3,613 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,613)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
PNGDec commit 8abf6be was discovered to contain a FPE via SaveBMP at /linux/main.cpp. |
2Fedoraproject Varnish Cache Project2Fedora Varnish CacheJun 17, 2026 Aug 11, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backe...Show more |
1Microsoft 1Azure Site Recovery Vmware To Azure Jun 17, 2026 Aug 9, 2022 N/A· v4 6.2 MEDIUM· v3 N/A· v2 Azure Site Recovery Denial of Service Vulnerability |
1Microsoft 10Windows 10 Windows 11Windows 7+7 moreJun 17, 2026 Aug 9, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability |
1Microsoft 10Windows 10 Windows 11Windows 7+7 moreJun 17, 2026 Aug 9, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability |
1F Secure 8Atlant Cloud Protection For SalesforceElements Collaboration Protection+5 moreJun 17, 2026 Aug 5, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files it is possible that can crash the scanning engine. The exploit can be trigge...Show more |
1Redhat 3Integration Camel K Jboss FuseUndertowJun 17, 2026 Aug 5, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpServerRequestConduit implementation closes a connection without sending any response to the client/prox...Show more |
In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can cause an increase in disk resource utilization. Note: Software versions which have reached End of Tech...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 Aug 4, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an HTTP2 profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilizati...Show more |
1F5 2Big Ip Access Policy Manager Big Ip Ssl OrchestratorJun 17, 2026 Aug 4, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when a BIG-IP APM access policy with Service Connect agent is configured on a virtual server, undisclosed requests can cause an i...Show more |
v8n is a javascript validation library. Versions of v8n prior to 1.5.1 were found to have an inefficient regular expression complexity in the `lowercase()` and `uppercase()` regex which could lead to a denial of service...Show more |
2Fedoraproject Rust Websocket Project2Fedora Rust WebsocketJun 17, 2026 Aug 1, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connections can cause an out-of-memory (OOM) process abort in a client or a server. The root cause of the i...Show more |
1Openzeppelin 4Contracts Contracts UpgradeableOpenzeppelin Eth+1 moreJun 17, 2026 Aug 1, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbounded gas consumption by returning a lot of data, while it is generally...Show more |
Juniper is a GraphQL server library for Rust. Affected versions of Juniper are vulnerable to uncontrolled recursion resulting in a program crash. This issue has been addressed in version 0.15.10. Users are advised to upg...Show more |
1Ovarro 8Tbox Lt2 530 Firmware Tbox Lt2 532 FirmwareTbox Lt2 540 Firmware+5 moreJun 17, 2026 Jul 28, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system. |
A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption. The bug could be exploited when loading a model in Apache MXNet that has a speciall...Show more |
An issue was discovered in H96 Smart TV Box H96 Pro Plus allows attackers to corrupt files via calls to the saveDeepColorAttr service.unk |
Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264. |
The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Sla...Show more |
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, a large response received by the viaduct WSClient...Show more |